PT-2026-56481 · Tooljet · Tooljet
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ToolJet versions prior to 3.20.180
Description
The render preview deployment workflow interpolates the
github.event.comment.body variable directly into a bash conditional within a run step. This allows a GitHub user with permission to comment on an open pull request to execute arbitrary shell commands on the CI runner and exfiltrate deployment secrets.Recommendations
Update to version 3.20.180.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tooljet